Recent Breaches
Breaches
2026PowerSchool62.4M records stolen2026DISA Global Solutions3.3M records stolen2026Globe Life850K records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026Co-operative Group6.5 million members (names, contact details, dates of birth) records stolen2026HarrodsAttempted intrusion, limited disruption records stolen2026Legal Aid Agency (Ministry of Justice)2.1 million applicants (financial, criminal, contact data since 2010) records stolen2026Adidas UKCustomer contact details (subset) records stolen2026Peter Green ChilledOrder and logistics data records stolen2026Jaguar Land RoverProduction and IT systems disrupted records stolen2026Collins Aerospace (RTX)Check-in and boarding disruption across Heathrow, Brussels, Berlin records stolen2026PowerSchool62.4M records stolen2026DISA Global Solutions3.3M records stolen2026Globe Life850K records stolen
View All →
Compliance

Regulatory alignment, mapped to Firevault

We map Firevault OSS and Control to the frameworks that matter most: NIS2, DORA, UK GDPR, ISO 27001, PCI DSS, CAF, FCA, Cyber Essentials Plus, NHS DSPT and the SRA. Alignment, not a certification claim.

Framework matrix

11

Frameworks mapped to Firevault

OSS & Control coverage

24h

NIS2 significant-incident window

EU Directive 2022/2555

72h

UK GDPR breach notification window

ICO / Article 33

CAF-aligned

Controls mapped to NCSC outcomes

Alignment, not certification

How we talk about compliance

Alignment, evidenced. Not certification, claimed.

Regulators do not ask for a badge. They ask for demonstrable technical and organisational measures, proportionate to the risk. Firevault OSS takes data offline. Control governs the path used to reach systems and data. Both produce evidence a regulator or auditor can read.

Where we say CAF-aligned, we mean controls mapped to NCSC CAF outcomes. Where we say Article 32 supporting, we mean measures a controller can point to. We do not issue certifications and do not accept audit outcomes on your behalf.

Core frameworks

The three that drive most conversations.

NIS2, DORA and UK GDPR set the tone for how regulators expect crown-jewel data and critical services to be protected.

Sector & standards coverage

Standards, sector rules and certifications.

ISO 27001, NCSC CAF, PCI DSS, FCA operational resilience, Cyber Essentials Plus, NHS DSPT and SRA. Mapped, not marketed.

Framework matrix
Product lines

Two lines. Different evidence.

Most compliance programmes use both: OSS for recoverable copies and confidentiality, Control for path governance and access windows.

Offline Secure Storage

Recoverable copies held offline. Supports Article 32 measures, NIS2 continuity, ISO 27001 A.8/A.10 and DORA recovery.

Explore Offline

Control

Path governance for IT and OT. Supports NIS2 supply chain, CAF Objective B, PCI DSS need-to-know and FCA impact tolerances.

Explore Control
Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Map Firevault to your regulator's language.

Send us the frameworks that apply to your organisation. We will map OSS and Control controls to the specific outcomes your auditor is testing against.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy